Summary
Overview
Work History
Education
Skills
Certification
Languages
Interests
Timeline
Amrit Poojari

Amrit Poojari

Thane

Summary

Seasoned Information Security Professional with over a decade of expertise in Cybersecurity , spanning Banking & Finance, Healthcare, and Consumer Products. Adept at Risk Assessment, Security Policy Implementation, Secure Architecture Design & Review, and Threat Modeling for cloud and on-premises deployments.

Possesses hands-on experience in Penetration Testing for applications and networks, coupled with strong project management skills in delivering Enterprise Vulnerability Assessment and Penetration Testing (VAPT) solutions.

Successfully operationalized security frameworks to enhance organizational security posture.

Strategic cybersecurity advisor, guiding security initiatives across diverse use cases and domains. Experienced in team building and managing cutting-edge security solutions, including IBM AppScan, Checkmarx, Blackduck, Acunetix, Qualys (EDR, WAF, WAS), and other Vulnerability Management (VM) solutions.

Recipient of multiple awards and recognitions for cybersecurity excellence. Well-versed in OWASP, SANS methodologies, and holds industry-recognized certifications, including GIAC (GDSA), OSCP, Microsoft Azure Cloud Security, ECSA, CEH, WAF, and Secure Coding.

Overview

11
11
years of professional experience
7
7
Certification

Work History

Lead Security Engineer

Mastercard
06.2022 - Current
  • Overseeing Product Security for a globally deployed payment application, including Wallet, P2P transactions, BNPL, and other financial services.
  • Driving Security by Design initiatives, collaborating with developers to embed security best practices into application development, strengthening the overall security posture of critical payment products.
  • Conducting Threat Modeling to proactively identify vulnerabilities, mitigate risks, and integrate security controls across all phases of the Software Development Life Cycle (SDLC).
  • Actively engaging in application architecture reviews, ensuring secure design principles are applied from inception to deployment.

Key Achievements & Deliverables

  • Developed and deployed new security features for a global payment wallet application, enhancing protection against emerging cyber threats.
  • Led security oversight for Wallet Payment, Tokenization, and Issuer-Acquirer Merchant integrations, safeguarding financial transactions at scale.
  • Fixed security issues from Blackduck and Checkmarx and helped team to plan and mitigate various application security testing.
  • Conducted security assessments for regulatory applications across multiple regions, particularly in Card Dispute Resolution, ensuring compliance and risk mitigation.
  • Recommended security system improvements, conducting risk analyses to define effective security countermeasures.
  • Improvised enterprise-wide security standards and procedures, aligning security strategies with business objectives.
  • Authored detailed security and vulnerability reports, analyzing attack vectors and providing actionable remediation plans.
  • Delivered security awareness training, strengthening employee resilience against phishing, ransomware, and other cyber threats.
  • Contributed to daily security operations, collaborating across teams to maintain and enhance the organization's security framework.

Senior Security Engineer

Mastercard
06.2021 - 06.2022
  • Managing BAU security process for 8 internal applications
  • Reviewing third party SAAS solutions with respect to architecture, deployment, security for over 10 products
  • Contributing in S-SDLC efforts for secure code design
  • Worked well in a team setting, providing support and guidance.
  • Demonstrated strong organizational and time management skills while managing multiple projects.

Technical Application Security Manager

Qualys
07.2020 - 06.2021
  • Led the Application Penetration Testing team, proactively identifying and mitigating vulnerabilities across Qualys products, networks, and endpoints, strengthening the overall security posture.
  • Implemented and operationalized a Web Application Firewall (WAF) across all product lines, significantly enhancing protection against web-based threats.
  • Drove continuous security improvement initiatives, integrating DevSecOps practices and advancing application security across development pipelines.
  • Personally identified and remediated critical vulnerabilities in Qualys products, preventing potential exploits and ensuring secure software releases.
  • Designed and operationalized a Bug Bounty program, incentivizing ethical hacking to enhance product security through responsible vulnerability disclosure.
  • Investigated security incidents, authored detailed forensic reports, and presented findings to executive leadership, driving informed decision-making.
  • Managed contract negotiations, budget planning, training programs, and performance reviews, ensuring efficient resource allocation and team development.
  • Led a team of three security professionals, fostering skill development and enhancing overall team effectiveness.
  • Evaluated security systems and procedures, recommending strategic improvements to strengthen organizational security.

Technical Manager Application

Axis Bank
04.2019 - 06.2020
  • Managed team of penetration testers responsible for testing Bank's critical infrastructure
  • Finding critical bugs in production applications as part of the Advanced PT activity Conducting application security assessments activities for Web Applications including Web services and actively participating in closure of security issues
  • Conducting application security assessments activities for Mobile applications including Android & iOS and actively participating in closure of security issues
  • Implemented security awareness programs and instituted compliance metrics to decrease enterprise risks
  • Established polices, SOPs and security standards in accordance with federal regulations
  • Evaluation & Implementation of security solutions for enhancing the security posture of the organization
  • Implement & design policies for web application firewall (Akamai & Imperva)

Key Project Deliveries

  • Achieved WAF blocking for external facing banking applications for AxisBank
  • Implemented Anti Malware security solutions for 8 Axis mobile applications
  • Successfully ran Red team / Blue team exercises as BAU Achieved 100% testing in calendar activities for source code review and penetration testing YoY
  • Achieved around 70% automation in application security stack by implementing tools like Acunetix, Checkmarx (SAST & IAST), Appknox
  • Performed security architecture review on 30 large enterprise applications
  • Liaised between business and technology units to manage delivery schedules for applications.
  • Gathered requirements and maintained communication between project teams, internal clients and external stakeholders.
  • Communicated project status and change management metrices with upper management
  • Analyzed company processes to determine outsourcing feasibility.
  • Increased employee productivity by 60% through training and mentorship.
  • Prepared status charts for weekly management meetings and shared updates to upcoming work alike

Deputy Technical Manager

Axis Bank
11.2016 - 03.2019
  • Developed suggestions for technical process improvements to optimize resources.
  • Managed implementation of new technological solutions resulting in increased efficiency.
  • Recruited and trained IT security team members.
  • Performed Application security testing for Web, Mobile and APIs

Sr. Security Engineer

CitiusTech
05.2016 - 11.2016
  • Responsible to carry out Application security testing for a major US client in aviation industry
  • Policy review of the security tools implemented as well as hardening of OS for ECG machine
  • Worked effectively in fast-paced environments.

Team Lead & Sr. Security Analyst

Paladion Networks
03.2015 - 05.2016

Leading a group of Security professionals for a Top Financial institute in India

  • Worked on managing client queries, planning and strategizing security activities & risk mitigation with clients and regular meetings and discussions
  • Review team member's assessments for all VAPT activities
  • Strategizing & Schedule overall scope of Vulnerability managements assignments
  • Recommend improvements in security systems and procedures.
  • Performed risk analyses to identify appropriate security countermeasures.
  • Conducted security audits to identify vulnerabilities.
  • Leading PCI Audits, Application security, APT, ASV Scans
  • Monthly discussion with client's application owners and presentation on the findings and the recommendations to Business Heads/Application Owners
  • Tracking application vulnerabilities on the client environment and giving timely suggestions and mitigation controls for vulnerability closure
  • Suggesting new Tools & Technologies to Clients, conducting POC's for tools and sharing Comparison reports.

Analyst

Paladion Networks
01.2014 - 04.2015
  • Projects include short term and long term assignments for various Banking and Financial sectors, Conducted Web Application testing for various Banking applications
  • Projects include Security Configuration Audits, Hardening of Servers,Databases and Network devices
  • Projects include Black box penetration testing of Servers,Databases and Network devices both using tools and Manually
  • Conducted over 80+ Web application testing.
  • Performed audits of subsidiaries to protect shareholders and potential investors from fraudulent or unrepresentative financial claims.

Education

Bachelor of Engineering - Information Technology

Siddhant College of Engineering, Pune
03-2013

High School Diploma -

K. J. Somaiya Institute of Technology, Mumbai
2008

Skills

  • Application & Infrastructure Security
  • Secure Design & Architecture Review
  • Vulnerability Assessment
  • Penetration testing
  • Cloud security
  • Red Team Operations
  • Security Solutions Operations
  • Team Building & Project Management
  • Intrusion Detection and Prevention

Certification

GIAC [GDSA] Defensible Security Architecture

OSCP - Offensive Security

Microsoft Azure Cloud Security

CPISI

Akamai-Kona Site Defender

Qualys Certified Specialist

ECSA

CEH


Languages

English
Bilingual or Proficient (C2)
Hindi
Bilingual or Proficient (C2)
Marathi
Bilingual or Proficient (C2)
Kannada
Intermediate (B1)

Interests

Travelling

Motorcycles

Learning About New Technology

Timeline

Lead Security Engineer - Mastercard
06.2022 - Current
Senior Security Engineer - Mastercard
06.2021 - 06.2022
Technical Application Security Manager - Qualys
07.2020 - 06.2021
Technical Manager Application - Axis Bank
04.2019 - 06.2020
Deputy Technical Manager - Axis Bank
11.2016 - 03.2019
Sr. Security Engineer - CitiusTech
05.2016 - 11.2016
Team Lead & Sr. Security Analyst - Paladion Networks
03.2015 - 05.2016
Analyst - Paladion Networks
01.2014 - 04.2015
Siddhant College of Engineering - Bachelor of Engineering, Information Technology
K. J. Somaiya Institute of Technology - High School Diploma,
Amrit Poojari